The Solutions

Automating Enforcement

Approach - A formal configuration management process is required in order to maintain a common security configuration across your enterprise. Automating enforcement will require policies, standard procedures, and standard tools. Policies must be established and supported by senior leadership within the organization. Variations should be minimized and violations should not be tolerated. Standard procedures are necessary to ensure predictable results and minimize errors and variances due to staff training or differences in skill level. The procedures should account for measuring and reporting compliance, repairing systems that are out of compliance, and applying changes approved by the Configuration Management team. A standard set of tools consistently configured across your enterprise establishes a platform for simplified management and enforcement.

Objective - Standard procedures for version control, automated compliance checking and reporting, and automated processes for restoring or updating systems with an equal emphasis on policies, procedures, and tools.